Description
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=2050228
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt
https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076
Related Vulnerabilities
CVE-2022-39250 Vulnerability in npm package matrix-js-sdk
CVE-2022-37435 Vulnerability in maven package org.apache.shenyu:shenyu-admin
CVE-2023-51075 Vulnerability in maven package cn.hutool:hutool-core
CVE-2023-37960 Vulnerability in maven package io.jenkins.plugins:mathworks-polyspace
CVE-2022-30500 Vulnerability in maven package com.jflyfox:jflyfox_jfinal